This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My computer has a virus which makes random noises.

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there, My computer has been infected by a virus, which makes my computer play random advertisements like sometimes it play something along the lines of 'The Ultimate Detergent' and several other weird noises. Please help, not only is the virus freaking me out but its not letting me use my speakers, because if I put them on the sounds play again. Any help would be greatly appreciated Thanks, Noob4Evar
Hello Noob4Evar and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the β€œAll clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
πŸ–ΌClick to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
πŸ–ΌClick to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<β€” ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
πŸ–ΌClick to load external image (Posted Image) Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window similar to this should open on your desktop:

    πŸ–ΌClick to load external image (Posted Image)

  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your deskop. Please post the contents of that file.

Please include the following in your next post:
  • DDS and Attach.txt logs
  • GMER log
  • MBRCheck log
Thanks for looking at my problem.

Here is the DDS.txt.


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 12:01:52.96 on 23/07/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Professional 6.1.7600.0.1252.44.1033.18.1790.867 [GMT 1:00]

SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
svchost.exe 4
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
svchost.exe 4

============== Pseudo HJT Report ===============

uStart Page = www.google.com
uDefault_Page_URL = hxxp://www.stonecomputers.co.uk
BHO: txthlpBHO Class: {060235dc-6d84-47bd-95d7-a4ef5099a59d} - c:\progra~1\texthe~1\readan~1\TE4470~1.DLL
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: ba3HelperObj Class: {a17b153f-2267-4161-a165-73dcd6c31bef} - c:\progra~1\texthe~1\readan~1\BA3BHO.DLL
BHO: Javaβ„’ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [KeNotify] c:\program files\toshiba\utilities\KeNotify.exe
mRun: [HWSetup] "c:\program files\toshiba\utilities\HWSetup.exe" hwSetUP
mRun: [ToshibaServiceStation] "c:\program files\toshiba\toshiba service station\ToshibaServiceStation.exe" /hide:60
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NIHomeAM] "c:\program files\netintelligence home\LiteClientAM.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRunOnce: [MessengerPlusLiveUninstall] "c:\users\admini~1\appdata\local\temp\MsgPlusUninstall.exe" /Cleanup
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office12\REFIEBAR.DLL
LSP: c:\windows\system32\NIHLSP.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

================= FIREFOX ===================

FF - ProfilePath - c:\users\admini~1\appdata\roaming\mozilla\firefox\profiles\c0zif4as.default\
FF - prefs.js: browser.search.selectedEngine - eBay.co.uk
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

β€”- FIREFOX POLICIES β€”-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

3 pxrts;pxrts
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? hwusbfake;Huawei DataCard USB Fake
R? MSSQLServerADHelper100;SQL Active Directory Helper Service
R? RsFx0103;RsFx0103 Driver
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? RtsUIR;Realtek IR Driver
R? SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS)
R? StorSvc;Storage Service
R? WatAdminSvc;Windows Activation Technologies Service
S? AMD External Events Utility;AMD External Events Utility
S? cfWiMAXService;ConfigFree WiMAX Service
S? ConfigFree Service;ConfigFree Service
S? epfwwfpr;epfwwfpr
S? MpFilter;Microsoft Malware Protection Driver
S? MpNWMon;Microsoft Malware Protection Network Driver
S? NILiteClient;Netintelligence Home Edition Client
S? pxkbf;pxkbf
S? pxscan;pxscan
S? pxsec;pxsec
S? RTL8167;Realtek 8167 NT Driver
S? rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver
S? SASDIFSV;SASDIFSV
S? SASKUTIL;SASKUTIL
S? ServiceMonitor;Service Monitor
S? TeamViewer5;TeamViewer 5
S? TMachInfo;TMachInfo
S? vwififlt;Virtual WiFi Filter Driver
S? WTGService;WTGService

=============== Created Last 30 ================

2010-07-23 09:35:58 0 d—–w- c:\program files\CCleaner
2010-07-22 22:41:18 68120 β€”-a-w- c:\windows\system32\PxSecure.dll-2710314
2010-07-22 22:40:46 53 β€”-a-w- c:\windows\wininit.ini
2010-07-21 18:29:07 0 d—–w- c:\users\admini~1\appdata\roaming\Malwarebytes
2010-07-21 18:28:01 38224 β€”-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-21 18:27:50 0 d—–w- c:\programdata\Malwarebytes
2010-07-21 18:27:48 20952 β€”-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-21 18:27:46 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-21 18:09:19 0 d-sh–w- c:\windows\ftpcache
2010-07-21 17:35:12 0 d—–w- c:\users\admini~1\appdata\roaming\SUPERAntiSpyware.com
2010-07-21 17:35:12 0 d—–w- c:\programdata\SUPERAntiSpyware.com
2010-07-21 17:35:00 0 d—–w- c:\program files\SUPERAntiSpyware
2010-07-21 17:26:34 2396859 β€”-a-w- C:\MGtools.exe
2010-07-21 09:14:08 0 d—–w- c:\programdata\ESET
2010-07-19 11:02:02 47 β€”-a-w- c:\windows\NeroDigital.ini
2010-07-18 19:11:29 0 d—–w- c:\users\admini~1\appdata\roaming\InternetEverywhere
2010-07-18 13:17:39 0 d—–w- c:\windows\system32\Temp
2010-07-18 11:30:44 0 d—–w- c:\program files\PFConfig
2010-07-18 11:08:49 0 d—–w- c:\program files\TeamViewer
2010-07-16 14:17:26 0 d—–w- c:\program files\Messenger Plus! Live
2010-07-11 13:12:31 0 d—–w- c:\users\admini~1\appdata\roaming\Texthelp Systems
2010-07-10 10:32:07 0 d—–w- c:\users\admini~1\appdata\roaming\HTNetMeter
2010-07-10 10:32:00 0 d—–w- c:\program files\HooTech
2010-07-10 10:22:21 0 d—–w- c:\users\admini~1\appdata\roaming\uTorrent
2010-07-10 10:14:57 0 d—–w- c:\program files\QS
2010-07-10 10:14:54 0 d—–w- c:\users\admini~1\appdata\roaming\TeamViewer
2010-07-10 10:14:47 0 d—–w- c:\users\administrator\temp
2010-07-10 10:08:25 0 d—–w- c:\users\admini~1\appdata\roaming\NetMeter
2010-07-10 10:08:18 0 d—–w- c:\program files\NetMeter
2010-07-09 15:35:15 0 β€”-a-w- c:\users\administrator\jagex__preferences3.dat
2010-07-09 15:35:14 99 β€”-a-w- c:\users\administrator\jagex_runescape_preferences2.dat
2010-07-09 15:34:49 46 β€”-a-w- c:\users\administrator\jagex_runescape_preferences.dat
2010-07-08 16:50:33 6576 β€”β€”w- C:\bootsqm.dat
2010-07-06 16:11:25 0 d—–w- c:\users\administrator\Tracing
2010-06-26 11:41:32 5504 β€”β€”w- c:\windows\system32\drivers\imagedrv.sys
2010-06-26 11:41:32 125184 β€”β€”w- c:\windows\system32\drivers\imagesrv.sys
2010-06-26 11:41:12 106496 β€”-a-w- c:\windows\system32\TwnLib20.dll
2010-06-26 11:41:11 476320 β€”β€”w- c:\windows\system32\ImagXpr7.dll
2010-06-26 11:41:11 471040 β€”β€”w- c:\windows\system32\ImagXRA7.dll
2010-06-26 11:41:11 262144 β€”β€”w- c:\windows\system32\ImagXR7.dll
2010-06-26 11:41:11 1568768 β€”β€”w- c:\windows\system32\ImagX7.dll
2010-06-26 11:41:11 155648 β€”-a-w- c:\windows\system32\NeroCheck.exe
2010-06-26 11:33:03 0 d—–w- c:\program files\uTorrent
2010-06-24 20:28:39 99176 β€”-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-24 20:28:39 297808 β€”-a-w- c:\windows\system32\mscoree.dll
2010-06-24 20:28:39 295264 β€”-a-w- c:\windows\system32\PresentationHost.exe
2010-06-24 20:28:38 49472 β€”-a-w- c:\windows\system32\netfxperf.dll
2010-06-24 20:28:38 1130824 β€”-a-w- c:\windows\system32\dfshim.dll
2010-06-24 05:48:48 1286456 β€”-a-w- c:\windows\system32\ntdll.dll
2010-06-24 05:48:47 641536 β€”-a-w- c:\windows\system32\CPFilters.dll
2010-06-24 05:48:46 417792 β€”-a-w- c:\windows\system32\msdri.dll
2010-06-24 05:48:45 204288 β€”-a-w- c:\windows\system32\MSNP.ax
2010-06-24 05:48:45 199680 β€”-a-w- c:\windows\system32\mpg2splt.ax

==================== Find3M ====================

2010-06-10 18:42:49 0 β€”ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2010-06-01 17:37:48 221568 β€”β€”w- c:\windows\system32\MpSigStub.exe
2010-05-27 07:24:13 34304 β€”-a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49:37 293888 β€”-a-w- c:\windows\system32\atmfd.dll
2010-05-21 05:18:06 977920 β€”-a-w- c:\windows\system32\wininet.dll
2010-05-01 14:49:25 2326528 β€”-a-w- c:\windows\system32\win32k.sys
2010-04-27 13:45:56 72856 β€”-a-w- c:\windows\system32\xliveinstallhost.exe
2010-04-27 13:45:56 187544 β€”-a-w- c:\windows\system32\xliveinstall.dll
2009-07-14 04:56:42 31548 β€”-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 β€”-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 β€”-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 β€”-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 β€”-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 β€”-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 β€”-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 β€”-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 12:05:16.98 ===============

Here is the GMER log.

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-23 12:31:26
Windows 6.1.7600
Running: 4y0kpw4m.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\fgrdapog.sys


β€”- System - GMER 1.0.15 β€”-

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2BAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E13634
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E13898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2B6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2BF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 82E2C1A8

β€”- Kernel code sections - GMER 1.0.15 β€”-

.text ntkrnlpa.exe!ZwSaveKeyEx + 13AD 82A44599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82A68F52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x8DC19000, 0x2D5378, 0xE8000020]
.text peauth.sys 9715BC9D 28 Bytes [5E, F6, F5, E3, 86, 19, DC, …]
.text peauth.sys 9715BCC1 28 Bytes [5E, F6, F5, E3, 86, 19, DC, …]
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 9D0BF000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, …]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 9D0BF123 629 Bytes [A5, 0B, 9D, FE, 05, 34, A5, …]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 9D0BF399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, …]
PAGE spsys.sys!?SPRevision@@3PADA + 538F 9D0BF3FF 136 Bytes [18, 5D, C2, 14, 00, 8B, FF, …]
PAGE spsys.sys!?SPRevision@@3PADA + 5418 9D0BF488 11 Bytes [89, 15, 3C, A5, 0B, 9D, E9, …] {MOV [0x9d0ba53c], EDX; JMP 0x240bb}
PAGE …

β€”- User code sections - GMER 1.0.15 β€”-

.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!CreateWindowExW 75500E51 5 Bytes JMP 6F7F8157 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxIndirectParamW 75524AA7 5 Bytes JMP 6F91F5E8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxParamW 7552564A 5 Bytes JMP 6F714BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxParamA 7553CF6A 5 Bytes JMP 6F91F585 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!DialogBoxIndirectParamA 7553D29C 5 Bytes JMP 6F91F64B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxIndirectA 7554E8C9 5 Bytes JMP 6F91F51A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxIndirectW 7554E9C3 5 Bytes JMP 6F91F4AF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxExA 7554EA29 5 Bytes JMP 6F91F44D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2500] USER32.dll!MessageBoxExW 7554EA4D 5 Bytes JMP 6F91F3EB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Mozilla Firefox\firefox.exe[3396] ntdll.dll!LdrLoadDll 770FF625 5 Bytes JMP 011713F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!UnhookWindowsHookEx 754FCC7B 5 Bytes JMP 6F80835E C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!CallNextHookEx 754FCC8F 5 Bytes JMP 6F7E9D5C C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!CreateWindowExW 75500E51 5 Bytes JMP 6F7F8157 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!SetWindowsHookExW 7550210A 5 Bytes JMP 6F7A4633 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxIndirectParamW 75524AA7 5 Bytes JMP 6F91F5E8 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxParamW 7552564A 5 Bytes JMP 6F714BA7 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxParamA 7553CF6A 5 Bytes JMP 6F91F585 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!DialogBoxIndirectParamA 7553D29C 5 Bytes JMP 6F91F64B C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxIndirectA 7554E8C9 5 Bytes JMP 6F91F51A C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxIndirectW 7554E9C3 5 Bytes JMP 6F91F4AF C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxExA 7554EA29 5 Bytes JMP 6F91F44D C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] USER32.dll!MessageBoxExW 7554EA4D 5 Bytes JMP 6F91F3EB C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] ole32.dll!OleLoadFromStream 76C75B88 5 Bytes JMP 6F91F946 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[4344] ole32.dll!CoCreateInstance 76CC57FC 5 Bytes JMP 6F7F8C45 C:\Windows\system32\IEFRAME.dll (Internet Browser/Microsoft Corporation)

β€”- Devices - GMER 1.0.15 β€”-

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 rdyboost.sys (ReadyBoost Driver/Microsoft Corporation)

Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

β€”- Registry - GMER 1.0.15 β€”-

Reg HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlId 136
Reg HKLM\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex@pkm:catalog:LastCatalogCrawlModified 4
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@CrawlType 2
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@InProgress 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@DoneAddingCrawlSeeds 1
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@IsCatalogLevel 0
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\137@LogStartAddId 7
Reg HKLM\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6@CrawlNumberInProgress 137

β€”- EOF - GMER 1.0.15 β€”-

Here is the log of MBRCheck.

MBRCheck, version 1.1.1

Β© 2010, AD



\\.\C: –> \\.\PhysicalDrive0

\\.\D: –> \\.\PhysicalDrive0



Size Device Name MBR Status

——————————————–

149 GB \\.\PhysicalDrive0 Known-bad MBR code detected (Whistler / Black Internet)!





Found non-standard or infected MBR.

Enter 'Y' and hit ENTER for more options, or 'N' to exit:



Done! Press ENTER to exit…

The attach.txt is here. πŸ“ŽAttach.txt
Noob4Evar,

πŸ–ΌClick to load external image (Posted Image) P2P - I see you have P2P software (uTorrent) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to malware infections. Malware authors use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs. If you choose to keep these applications, please do not use them until our fixes at WTT are complete.

πŸ–ΌClick to load external image (Posted Image) You are infected with a Rootkit. I recommend that you limit your online activity until we have your system clean and change all your passwords from a different, clean computer.

This infection will take several steps to clean. Here are your first instructions:

πŸ–ΌClick to load external image (Posted Image) Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt.
Please include the following in your next post:
  • ComboFix log
Here is the ComboFix log: ComboFix 10-07-22.06 - Administrator 23/07/2010 20:27:48.1.1 - x86 Microsoft Windows 7 Professional 6.1.7600.0.1252.44.1033.18.1790.993 [GMT 1:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\system volume information\Chkdsk c:\system volume information\Chkdsk\Chkdsk20100708165032.log c:\system volume information\Chkdsk\Chkdsk20100722070108.log c:\windows\system32\NIHLSP.dll c:\windows\system32\Temp . ((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 ))))))))))))))))))))))))))))))) . 2010-07-23 19:36 . 2010-07-23 19:42 ——– d—–w- c:\users\Administrator\AppData\Local\temp 2010-07-23 19:36 . 2010-07-23 19:36 ——– d—–w- c:\users\Learner\AppData\Local\temp 2010-07-23 19:36 . 2010-07-23 19:36 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-07-23 19:25 . 2010-07-23 19:25 ——– d—–w- C:\32788R22FWJFW 2010-07-23 09:35 . 2010-07-23 09:36 ——– d—–w- c:\program files\CCleaner 2010-07-21 18:29 . 2010-07-21 18:29 ——– d—–w- c:\users\Administrator\AppData\Roaming\Malwarebytes 2010-07-21 18:27 . 2010-07-21 18:27 ——– d—–w- c:\programdata\Malwarebytes 2010-07-21 18:09 . 2010-07-21 18:09 ——– d-sh–w- c:\windows\ftpcache 2010-07-21 17:35 . 2010-07-21 17:35 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2010-07-21 17:26 . 2010-07-21 17:26 2396859 β€”-a-w- C:\MGtools.exe 2010-07-18 19:11 . 2010-07-18 20:27 ——– d—–w- c:\users\Administrator\AppData\Roaming\InternetEverywhere 2010-07-18 11:30 . 2010-07-18 13:01 ——– d—–w- c:\program files\PFConfig 2010-07-18 11:08 . 2010-07-18 11:08 ——– d—–w- c:\program files\TeamViewer 2010-07-18 09:16 . 2010-07-18 09:16 94062 β€”-a-w- c:\programdata\Microsoft\Microsoft Antimalware\LocalCopy\{D41C9945-E87C-4C5F-8C3A-9FAA69CEEA77}-ctv6920.exe 2010-07-16 14:17 . 2010-07-23 09:31 ——– d—–w- c:\program files\Messenger Plus! Live 2010-07-11 13:12 . 2010-07-11 13:12 ——– d—–w- c:\users\Administrator\AppData\Roaming\Texthelp Systems 2010-07-10 10:32 . 2010-07-10 10:32 ——– d—–w- c:\users\Administrator\AppData\Roaming\HTNetMeter 2010-07-10 10:32 . 2010-07-21 16:13 ——– d—–w- c:\program files\HooTech 2010-07-10 10:22 . 2010-07-23 08:56 ——– d—–w- c:\users\Administrator\AppData\Roaming\uTorrent 2010-07-10 10:14 . 2010-07-10 10:14 ——– d—–w- c:\program files\QS 2010-07-10 10:14 . 2010-07-18 11:09 ——– d—–w- c:\users\Administrator\AppData\Roaming\TeamViewer 2010-07-10 10:14 . 2010-07-10 10:14 ——– d—–w- c:\users\Administrator\temp 2010-07-10 10:08 . 2010-07-10 10:08 ——– d—–w- c:\users\Administrator\AppData\Roaming\NetMeter 2010-07-10 10:08 . 2010-07-10 10:20 ——– d—–w- c:\program files\NetMeter 2010-07-09 15:35 . 2010-07-09 15:35 0 β€”-a-w- c:\users\Administrator\jagex__preferences3.dat 2010-07-09 15:35 . 2010-07-18 10:58 99 β€”-a-w- c:\users\Administrator\jagex_runescape_preferences2.dat 2010-07-09 15:34 . 2010-07-18 10:37 46 β€”-a-w- c:\users\Administrator\jagex_runescape_preferences.dat 2010-07-08 16:50 . 2010-07-08 16:50 6576 β€”β€”w- C:\bootsqm.dat 2010-07-06 21:08 . 2010-07-06 21:08 ——– d—–w- c:\users\Administrator\AppData\Local\TOSHIBA_Corporation 2010-07-06 20:46 . 2010-07-06 20:46 ——– d—–w- c:\windows\Sun 2010-07-06 16:27 . 2010-07-06 16:27 ——– d—–w- c:\users\Administrator\AppData\Local\Toshiba 2010-07-06 16:11 . 2010-07-23 19:41 ——– d—–w- c:\users\Administrator\Tracing 2010-07-06 16:07 . 2010-07-06 16:07 0 β€”-a-w- c:\windows\nsreg.dat 2010-07-06 16:07 . 2010-07-06 16:07 ——– d—–w- c:\users\Administrator\AppData\Local\Mozilla 2010-07-06 15:58 . 2010-07-08 16:44 ——– d—–w- c:\users\Administrator\AppData\Local\Adobe 2010-07-06 15:58 . 2010-07-06 15:58 66760 β€”-a-w- c:\users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2010-07-01 08:33 . 2010-07-01 08:33 ——– d—–w- c:\users\Learner\AppData\Local\Diagnostics 2010-06-26 19:20 . 2010-06-26 19:20 ——– d—–w- c:\users\Learner\AppData\Local\Ahead 2010-06-26 11:41 . 2004-03-02 16:37 125184 β€”β€”w- c:\windows\system32\drivers\imagesrv.sys 2010-06-26 11:41 . 2004-03-02 16:37 5504 β€”β€”w- c:\windows\system32\drivers\imagedrv.sys 2010-06-26 11:41 . 2000-06-26 10:45 106496 β€”-a-w- c:\windows\system32\TwnLib20.dll 2010-06-26 11:41 . 2004-07-26 16:16 476320 β€”β€”w- c:\windows\system32\ImagXpr7.dll 2010-06-26 11:41 . 2004-07-26 16:16 471040 β€”β€”w- c:\windows\system32\ImagXRA7.dll 2010-06-26 11:41 . 2004-07-26 16:16 262144 β€”β€”w- c:\windows\system32\ImagXR7.dll 2010-06-26 11:41 . 2004-07-26 16:16 1568768 β€”β€”w- c:\windows\system32\ImagX7.dll 2010-06-26 11:41 . 2001-07-09 10:50 155648 β€”-a-w- c:\windows\system32\NeroCheck.exe 2010-06-26 11:41 . 2010-06-26 11:41 ——– d—–w- c:\program files\Ahead 2010-06-26 11:41 . 2010-06-26 11:41 ——– d—–w- c:\program files\Common Files\Ahead 2010-06-26 11:33 . 2010-06-26 11:33 ——– d—–w- c:\program files\uTorrent 2010-06-26 11:32 . 2010-06-26 11:40 ——– d—–w- c:\users\Learner\AppData\Roaming\uTorrent 2010-06-24 20:28 . 2009-11-25 11:47 99176 β€”-a-w- c:\windows\system32\PresentationHostProxy.dll 2010-06-24 20:28 . 2009-11-25 11:47 297808 β€”-a-w- c:\windows\system32\mscoree.dll 2010-06-24 20:28 . 2009-11-25 11:47 295264 β€”-a-w- c:\windows\system32\PresentationHost.exe 2010-06-24 20:28 . 2009-11-25 11:47 49472 β€”-a-w- c:\windows\system32\netfxperf.dll 2010-06-24 20:28 . 2009-11-25 11:47 1130824 β€”-a-w- c:\windows\system32\dfshim.dll 2010-06-24 05:48 . 2010-03-24 06:37 1286456 β€”-a-w- c:\windows\system32\ntdll.dll 2010-06-24 05:48 . 2010-05-09 09:14 641536 β€”-a-w- c:\windows\system32\CPFilters.dll 2010-06-24 05:48 . 2010-05-09 09:14 417792 β€”-a-w- c:\windows\system32\msdri.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-23 19:43 . 2010-04-19 09:47 ——– d—–w- c:\program files\Netintelligence Home 2010-07-23 09:23 . 2010-03-26 12:41 ——– d—–w- c:\program files\Microsoft 2010-07-15 15:59 . 2010-03-26 11:58 ——– d—–w- c:\programdata\Microsoft Help 2010-07-04 18:03 . 2010-06-19 15:54 99 β€”-a-w- c:\users\Learner\jagex_runescape_preferences2.dat 2010-07-04 16:08 . 2010-06-19 15:53 46 β€”-a-w- c:\users\Learner\jagex_runescape_preferences.dat 2010-06-29 17:57 . 2010-03-26 12:46 ——– d—–w- c:\program files\Microsoft Security Essentials 2010-06-26 05:33 . 2010-03-26 11:58 ——– d—–w- c:\program files\Microsoft.NET 2010-06-19 15:54 . 2010-06-19 15:54 0 β€”-a-w- c:\users\Learner\jagex__preferences3.dat 2010-06-18 20:44 . 2010-06-18 20:43 ——– d—–w- c:\program files\Windows Live Safety Center 2010-06-14 19:16 . 2010-06-14 19:16 ——– d—–w- c:\users\Learner\AppData\Roaming\TeamViewer 2010-06-10 18:42 . 2010-06-10 18:42 0 β€”ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2010-06-08 18:42 . 2010-06-08 18:42 ——– d—–w- c:\program files\Microsoft Office Outlook Connector 2010-06-08 18:42 . 2010-06-08 18:35 ——– d—–w- c:\program files\Windows Live 2010-06-08 16:39 . 2009-07-14 02:37 ——– d—–w- c:\program files\Windows Mail 2010-06-08 16:38 . 2010-03-26 12:01 ——– d—–w- c:\program files\Microsoft Silverlight 2010-06-08 15:57 . 2010-04-20 11:20 ——– d—–w- c:\users\Learner\AppData\Roaming\InternetEverywhere 2010-06-01 17:37 . 2010-03-24 15:47 221568 β€”β€”w- c:\windows\system32\MpSigStub.exe 2010-05-27 07:24 . 2010-06-11 06:28 34304 β€”-a-w- c:\windows\system32\atmlib.dll 2010-05-27 03:49 . 2010-06-11 06:28 293888 β€”-a-w- c:\windows\system32\atmfd.dll 2010-05-21 05:18 . 2010-06-11 06:28 977920 β€”-a-w- c:\windows\system32\wininet.dll 2010-05-01 14:49 . 2010-06-11 06:28 2326528 β€”-a-w- c:\windows\system32\win32k.sys 2010-04-28 06:44 . 2010-06-08 18:42 54632 β€”-a-w- c:\windows\system32\drivers\fssfltr.sys 2010-04-27 13:45 . 2010-04-27 13:45 72856 β€”-a-w- c:\windows\system32\xliveinstallhost.exe 2010-04-27 13:45 . 2010-04-27 13:45 187544 β€”-a-w- c:\windows\system32\xliveinstall.dll 2009-06-10 21:26 . 2009-07-14 02:04 9633792 –sha-r- c:\windows\Fonts\StaticCache.dat 2009-07-14 01:14 . 2009-07-13 23:42 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504] "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208] "KeNotify"="c:\program files\TOSHIBA\Utilities\KeNotify.exe" [2009-01-13 34088] "HWSetup"="c:\program files\TOSHIBA\Utilities\HWSetup.exe" [2009-06-02 425984] "ToshibaServiceStation"="c:\program files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888] "NIHomeAM"="c:\program files\Netintelligence Home\LiteClientAM.exe" [2009-10-27 1196544] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Launcher.lnk - c:\program files\InternetEverywhere\Launcher.exe [2010-4-16 472528] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] @="Service" R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2010-04-16 103040] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-07-30 171520] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-09 1343400] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2008-07-10 47128] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-30 366936] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-08-18 176128] S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [2009-08-10 185712] S2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448] S2 NILiteClient;Netintelligence Home Edition Client;c:\program files\Netintelligence Home\LiteClient.exe [2009-10-05 2359296] S2 ServiceMonitor;Service Monitor;c:\windows\system32\srvmon.exe [2009-08-25 712704] S2 TeamViewer5;TeamViewer 5;c:\program files\TeamViewer\Version5\TeamViewer_Service.exe [2010-05-21 173352] S2 WTGService;WTGService;c:\program files\InternetEverywhere\WTGService.exe [2009-09-09 308688] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-03-01 139776] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-04-16 996896] S3 TMachInfo;TMachInfo;c:\program files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512] . . β€”β€”- Supplementary Scan β€”β€”- . uStart Page = www.google.com IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office12\EXCEL.EXE/3000 LSP: c:\windows\system32\NIHLSP.DLL FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\c0zif4as.default\ FF - prefs.js: browser.search.selectedEngine - eBay.co.uk FF - prefs.js: browser.startup.homepage - www.google.com FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll β€”- FIREFOX POLICIES β€”- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); . - - - - ORPHANS REMOVED - - - - Toolbar-Locked - (no file) . β€”β€”β€”β€”β€”β€”β€” LOCKED REGISTRY KEYS β€”β€”β€”β€”β€”β€”β€” [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c6,6e,9e,53,4f,e7,99,4c,b4,bf,d3,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c6,6e,9e,53,4f,e7,99,4c,b4,bf,d3,\ [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (Administrator) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,55,40,9c,92,91,20,56,4d,8f,3d,7d,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,55,40,9c,92,91,20,56,4d,8f,3d,7d,\ [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.3G2" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.3GP" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.3G2" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.3GP" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ADTS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ADTS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ADTS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.AIFF" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.AIFF" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.AIFF" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ASF" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ASX" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.AU" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.AVI" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.CDA" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2t\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.M2TS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2ts\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.M2TS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m2v\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.m3u" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.M4A" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MP4" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MIDI" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MIDI" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mod\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MOV" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MP3" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MP3" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MP4" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MP4" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MPEG" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mts\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.M2TS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.MIDI" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.AU" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ts\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.TTS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tts\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.TTS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WAV" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WAX" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ASF" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WMA" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WMD" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WMS" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WMV" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.ASX" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WMZ" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WPL" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice] @Denied: (2) (Administrator) "Progid"="WMP11.AssocFile.WVX" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" [HKEY_USERS\S-1-5-21-3522361164-386633583-3207523654-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice] @Denied: (2) (Administrator) "Progid"="FirefoxHTML" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€” - - - - - - - > 'Explorer.exe'(2816) c:\program files\Netintelligence Home\NI_KEY.DLL . β€”β€”β€”β€”β€”β€”β€”β€” Other Running Processes β€”β€”β€”β€”β€”β€”β€”β€” . c:\program files\Microsoft Security Essentials\MsMpEng.exe c:\windows\system32\atieclxx.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe c:\windows\system32\conhost.exe c:\program files\Netintelligence Home\AMMon.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\windows\servicing\TrustedInstaller.exe c:\program files\Internet Explorer\iexplore.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\DllHost.exe c:\windows\system32\sppsvc.exe . ************************************************************************** . Completion time: 2010-07-23 20:48:10 - machine was rebooted ComboFix-quarantined-files.txt 2010-07-23 19:47 Pre-Run: 112,704,897,024 bytes free Post-Run: 112,820,813,824 bytes free - - End Of File - - A2AB51C866692449C4711DE85A220217 Also, the laptop can no longer access the internet although it can detect the wireless network. Need help restoring that please. Thanks.
Noob4Evar,

I see MGTools installed on this PC. If you have a topic open at MajorGeeks, please let them know you are being helped here so you don't tie up another helper. If you'd rather be helped there, let me know and I'll close the thread. Whatever you do, don't follow instructions from two different helpers.

πŸ–ΌClick to load external image (Posted Image) If your network icon appears on the Windows taskbar, then you can repair it by right-clicking on the icon and selecting Repair.

[external image: Posted Image]

If you have no task bar icon do this:
  • Click on the Start button.
  • Click on the Settings menu option.
  • Click on the Control Panel option.
  • When the Control Panel opens, double-click on the Network Connections icon. If your Control Panel is set to Category View, then double-click on Network and Internet Connections and then click on Network Connections at the bottom.
  • You will now see a list of available network connections. Locate the connection for your Wireless or Lan adapter and right-click on it.
  • click on the Repair menu option.

[external image: Posted Image]

Let the repair process perform its tasks and when it has finished, your Internet connection should be working again.

If that doesn't work - try the following:
  • Go to Start > Control Panel, and choose Network Connections.
  • Right click on your default connection, usually Local Area Connection for cable and DSL or Dial-up Connection if you are using Dial-up, and choose Properties.
  • Click the Networking tab
  • Double-click on the Internet Protocol (TCP/IP) item.
  • Write down the settings in case you should need to change them back.
  • Select the radio button that says "Obtain DNS servers automatically".
  • Click OK twice to get out of the properties screen and restart your computer.
  • If not prompted to reboot go ahead and reboot manually.
In I.E.
  • Check internet options settings.
  • Tools > Internet Options > Connections
  • LAN settings
  • Choose "automatically detect settings"
  • uncheck both proxy settings boxes
In FireFox
  • Click on Advanced -> Network -> Setttings…
  • the No Proxy option should be selected

Let me know when you finish and we will continue cleaning.
Hi, I do not have a topic open at MajorGeeks but I was browsing their forum for some help until my friend recommended me to come here. I cannot follow the instructions that you have given me as I am running Windows 7 (and those instructions seem to be for Windows XP). Sorry for any inconvenience caused and I am very grateful for your help.
Good enough, thanks.

Sorry, I posted the wrong OS instructions. If you have the network icon in your tray, right click it and select "Troubleshoot Problems" If you don't have a tray icon click Start >Control Panel > Network and Internet > Network and Sharing Center > Troubleshoot Problems

The Internet Options are at Start >Control Panel > Network and Internet > Internet Options

The rest of the instructions should be good.
Hi, I tried following the new instructions that you gave me but after accessing the "Troubleshoot Problems" I was given 5 categories to troubleshoot. I troubleshooted "Internet Connections" and "Network Adapter" (because they seemed relevant to my problem) but they both ended up with the result "Troubleshooting couldn't identify the problem."
πŸ–ΌClick to load external image (Posted Image) Follow these steps to use the reset command to reset TCP/IP manually:
  • To open a command prompt, press Start and type cmd into the search box. You should see cmd populate above, under Programs - right click on it and select "Run as administrator"
  • At the command prompt, type the following command and then press ENTER:
    netsh int ip reset
  • Reboot the computer.
Noob4Evar,

This will require getting a file from the infected PC to your working PC to upload for analysis, so you will need a CD or USB drive:

πŸ–ΌClick to load external image (Posted Image) Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)
Please go to one of the below sites to scan the following files:
virscan.org
Virus Total

click on Browse, and upload the following file for analysis:
C:\Qoobox\Quarantine\C\windows\system32\NIHLSP.dll.vir

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
Hi,

I used virscan.org. Here are the results:


VirSCAN.org Scanned Report :
Scanned time : 2010/07/24 18:47:29 (BST)
Scanner results: Scanners did not find malware!
File Name : NIHLSP.dll.vir
File Size : 69632 byte
File Type : PE32 executable for MS Windows (DLL) (GUI) Intel 80386 32-bi
MD5 : c75aa3f772403c0348b0cb88c7125196
SHA1 : bf73fc446ff81618837df75c08cf148e410133a6
Online report : http://virscan.org/report/5f5c038f8e007f9b…9e0e0fbe15.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 5.0.0.13 20100724011914 2010-07-24 5.67 -
AhnLab V3 2010.07.14.00 2010.07.14 2010-07-14 1.53 -
AntiVir 8.2.4.26 7.10.9.193 2010-07-23 0.28 -
Antiy 2.0.18 20100720.4834932 2010-07-20 0.02 -
Arcavir 2009 201006281601 2010-06-28 0.00 -
Authentium 5.1.1 201007241055 2010-07-24 1.29 -
AVAST! 4.7.4 100724-1 2010-07-24 0.01 -
AVG 8.5.793 271.1.1/3025 2010-07-24 0.25 -
BitDefender 7.90123.6569114 7.32963 2010-07-24 4.09 -
ClamAV 0.96.1 11425 2010-07-24 0.03 -
Comodo 4.0 5525 2010-07-24 1.18 -
CP Secure 1.3.0.5 2010.07.24 2010-07-24 0.06 -
Dr.Web 5.0.2.3300 2010.07.24 2010-07-24 8.90 -
F-Prot 4.4.4.56 20100724 2010-07-24 1.31 -
F-Secure 7.02.73807 2010.07.24.01 2010-07-24 0.20 -
Fortinet 4.1.143 12.181 2010-07-24 0.60 -
GData 21.566/21.210 20100724 2010-07-24 9.02 -
ViRobot 20100724 2010.07.24 2010-07-24 0.38 -
Ikarus T3.1.01.84 2010.07.24.76331 2010-07-24 7.36 -
JiangMin 13.0.900 2010.07.24 2010-07-24 1.30 -
Kaspersky 5.5.10 2010.07.24 2010-07-24 0.15 -
KingSoft 2009.2.5.15 2010.7.23.18 2010-07-23 0.82 -
McAfee 5400.1158 6053 2010-07-24 17.43 -
Microsoft 1.6004 2010.07.24 2010-07-24 5.79 -
Norman 6.05.11 6.05.00 2010-07-24 6.01 -
Panda 9.05.01 2010.07.24 2010-07-24 1.72 -
Trend Micro 9.120-1004 7.334.09 2010-07-24 0.00 -
Quick Heal 11.00 2010.07.24 2010-07-24 2.22 -
Rising 20.0 22.57.03.08 2010-07-23 1.39 -
Sophos 3.10.0 4.56 2010-07-24 3.50 -
Sunbelt 3.9.2432.2 6630 2010-07-23 14.12 -
Symantec 1.3.0.24 20100723.024 2010-07-23 0.05 -
nProtect 20100724.02 9171265 2010-07-24 10.99 -
The Hacker 6.5.2.1 v00324 2010-07-23 0.52 -
VBA32 3.12.12.6 20100723.0932 2010-07-23 3.08 -
VirusBuster 4.5.11.10 10.127.22/2053106 2010-07-24 2.72 -
Noob4Evar,

πŸ–ΌClick to load external image (Posted Image) Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above File::

DeQuarantine::
C:\Qoobox\Quarantine\C\windows\system32\NIHLSP.dll.vir
Quit::

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of the log in your next reply.

Once you've run the script and rebooted, try to repair your connection again.

Please include the following in your next post:
  • ComboFix log
The internet works now! Thank you so much! Here is the ComboFix log: C:\Qoobox\Quarantine\C\windows\system32\NIHLSP.dll.vir -> C:\windows\system32\NIHLSP.dll ( 69632 bytes )

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI